CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,714 vulnerabilities with CWE-94
CVE-2026-10529 LOW
westboy CicadasCMS Task Scheduling Management ScheduleJobController.java cross site scripting
CVSS 2.4
CVE-2026-10514 LOW
1Panel-dev CordysCRM RequestParamTrimConfig.java cross site scripting
CVSS 2.4
CVE-2026-10301 MEDIUM
itsourcecode Fees Management System 1.0 - Cross-Site Scripting via index.php page Parameter
CVSS 4.3
CVE-2026-25879 CRITICAL
Langroid < 0.63.0 - SQL Injection via LLM Prompt Injection
CVSS 9.8
CVE-2026-10289 MEDIUM
Hotel and Tourism Reservation System 1.0 - Cross-Site Scripting via Tour.php Name/Email/People/Number Parameters
CVSS 4.3
CVE-2026-9311 CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via Security Control Bypass
CVSS 9.0
CVE-2026-45132 CRITICAL
CloudPirates Open Source Helm Charts: GitHub Actions workflow leaks PAT and SSH signing key via unsafe credential handling
CVSS 10.0
CVE-2026-45131 CRITICAL
CloudPirates Helm Charts - GitHub Actions Secret Exfiltration
CVSS 10.0
CVE-2026-8931 CRITICAL
Disig Web Signer 2.0.3-2.5.3 - Remote Code Execution
CVE-2026-10247 LOW
SourceCodester Pharmacy Sales and Inventory System main create_generic_name cross site scripting
CVSS 3.5
CVE-2026-10246 LOW
SourceCodester Pharmacy Sales and Inventory System main create_medicine_presentation cross site scripting
CVSS 3.5
CVE-2026-10245 LOW
SourceCodester Pharmacy Sales and Inventory System main create_supplier cross site scripting
CVSS 3.5
CVE-2026-10244 LOW
SourceCodester Pharmacy Sales and Inventory System main create_medicine_name cross site scripting
CVSS 3.5
CVE-2026-45505 HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
CVSS 8.8
CVE-2026-42588 HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
CVSS 8.1
CVE-2026-10234 LOW
Mettle sendportal Campaign webview cross site scripting
CVSS 3.5
CVE-2026-10228 LOW
raisulislamg4 student_management_system_by_php admission_form_check.php cross site scripting
CVSS 3.5
CVE-2026-10175 MEDIUM
Aider-AI Aider Architect Mode auth.py editor_coder.run code injection
CVSS 6.3
CVE-2026-10173 MEDIUM
Orthanc Explorer 2 URL StudyList.vue cross site scripting
CVSS 4.3
CVE-2026-10153 MEDIUM
westboy CicadasCMS AbstractCacheManager.java search cross site scripting
CVSS 4.3
CVE-2026-10112 LOW
sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting
CVSS 2.4
CVE-2026-45697 CRITICAL
Formie: Pre-authenticated server-side template injection in Hidden fields
CVSS 9.8
CVE-2026-44287 MEDIUM
FastGPT: sandbox escape to RCE - code-sandbox regex /\bimport\s*\(/ is bypassable
CVSS 6.3
CVE-2026-41159 MEDIUM
Mermaid: Improper sanitization of configuration leads to CSS injection
CVSS 5.3
CVE-2026-45555 HIGH
Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagnostics Leads to Arbitrary Code Execution
CVSS 7.8
Details
Vulnerabilities 6,714
Exploit Likelihood Medium